How To

An Online Extortion Crisis Response Plan

Here's one CISO's plan if he receives an extortionist's threat

By Scott Berinato

May 01, 2005CSO — Here's one CISO's plan if he receives an extortionist's e-mail. (The CISO works for a large company but requested anonymity so as not to become a first-time target of extortion attempts.)

  1. Contact general counsel and CIO executive team (and whomever else they deem appropriate), and jointly make assessment of the company's risks as well as the credibility of the threat. Discuss all possible factors that could magnify the risks (such as impending big executive news or an acquisition).
  2. Recommend contact with appropriate electronic crimes law enforcement officials (LEOs) for tactical advice and (hopefully) assistance. (For example, are we the first to ever get this threat? Are these known perps? Has there been prior experience with them or with this MO?)
  3. If top management agrees to involve external LEOs, begin an investigation jointly with LEOs. Formulate detection and response strategy with them to prepare to acquire and preserve evidence.
  4. If senior management declines to involve external LEOs, whether or not they decide to pay, then expect to be tasked to assemble a "red team" to search for and eliminate the vulnerabilities that make the threat credible, and take other steps to diminish risk of attacks.
  5. Simultaneously expect to be working with crisis management teams, and especially the investor relations and corporate PR staff, to prepare an official position for the media. If a U.S.-based company, consider the Sarbanes-Oxley implications of every decision. That means senior finance folks will also need to be involved.
  6. Warm up disaster and business continuity plans and providers depending on the nature of the threat, perhaps increase backups in frequency or type. (For example, go to full nowinstead of incrementalfor critical systems at risk.)
    1. -S.B.

      Other stories by Scott Berinato

online extortion

RESOURCE CENTER
Loading...
VIRTUAL CONFERENCE
Security Directions: A Virtual Conference

Security Directions Available On Demand Sept. 30 - Dec. 30

Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.

» Register Now

WEBCAST
Protecting PII: How to Work with IT to Manage Risk

Compuware Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.

» View this Webcast

Featured Sponsors